Digital Forensics
In this immersive project-based unit, students play the role of cybersecurity experts solving a high-stakes cybercrime mystery in the world of esports. Each lesson contains new cybersecurity concepts that are necessary to interpret clues, challenges, and developments that build toward the resolution of the case.
In this activity, students will watch Episode 5 of the Netflix documentary series High Score, titled “Fight,” which explores the rise of fighting games, arcade competition, and the early fighting game community. Students will complete a 10-question worksheet that focuses on key ideas, important moments, and the impact of games such as Street Fighter II. Responses should be written in 1 complete sentence for each question and demonstrate understanding of the documentary content.
Students will analyze the history, growth, and cultural impact of fighting games and competitive gaming by watching High Score Episode 5: “Fight” and responding to questions using evidence from the documentary in complete sentences.
High Score: Fight! Worksheet
Final Broadcast Project
In a simulated press conference, students present their findings and prevention strategies. They reflect on lessons learned, discuss real-world cybersecurity applications, and consider career insights.
Students will be able to articulate the outcomes of their cybersecurity simulation through clear explanations during a simulated press conference.
Students will be able to evaluate the effectiveness of their defense strategies and identify areas for improvement.
Students will be able to connect their simulation experience to real-world cybersecurity challenges and career opportunities.
Students will be able to create and justify recommendations for preventing future cyberattacks based on their findings.
Students will be able to reflect on their team’s performance and the decisions made during the simulation, analyzing their impact on the final outcome.
Digital Forensic Test (Paper Copy Only)
Teams outline a strategy to prevent the final attack during the championship. In a mock cyber-defense scenario, students defend the network against simulated attacks and prepare their final investigative report and recommendations.
Students will be able to understand contingency planning and its role in cybersecurity.
Students will be able to create a comprehensive defense strategy to mitigate potential cyberattacks on critical systems.
Students will be able to respond effectively to simulated cyber threats in real-time, applying their knowledge of cybersecurity principles.
Students will be able to evaluate the outcomes of their defense strategies and propose improvements based on the scenario results.
Students will be able to prepare and present a professional investigative report that summarizes findings, actions taken, and recommendations for future security enhancements.
Gameplan: Mock Cyber-Defense Scenario Assignment, The Takedown Plan Quiz
Gaming Inflation Worksheet: See Projects Tab
Teams outline a strategy to prevent the final attack during the championship. In a mock cyber-defense scenario, students defend the network against simulated attacks and prepare their final investigative report and recommendations.
Students will be able to understand contingency planning and its role in cybersecurity.
Students will be able to create a comprehensive defense strategy to mitigate potential cyberattacks on critical systems.
Students will be able to respond effectively to simulated cyber threats in real-time, applying their knowledge of cybersecurity principles.
Students will be able to evaluate the outcomes of their defense strategies and propose improvements based on the scenario results.
Students will be able to prepare and present a professional investigative report that summarizes findings, actions taken, and recommendations for future security enhancements.
Gameplan: Mock Cyber-Defense Scenario Assignment, The Takedown Plan Quiz
Students identify a critical piece of evidence linking the breach to an external hacker group. They implement security protocols to protect the tournament’s systems and strategize their final approach to uncover the mastermind.
Students will be able to identify and analyze critical evidence linking the breach to an external hacker group.
Students will be able to implement key security protocols, such as monitoring suspicious IP activity and updating access controls, while strategizing their final approach to expose the mastermind behind the attack.
Students will be able to determine the origin and actors behind a cyberattack by analyzing evidence.
Students will be able to apply technical safeguards to prevent further breaches.
Students will be able to develop a systematic approach to counter an advanced cyber threat.
Gameplan: Implementing Security Protocols Assignment, The Breakthrough Quiz
A mysterious ally sends an email containing valuable new clues. Teams work to decrypt hidden data files, revealing partial plans of the cybercriminals. Students share findings and regroup to discuss next steps.
Students will be able to analyze new clues and decrypt hidden data files to uncover partial plans of the cybercriminals.
Students will be able to connect newly decrypted information to prior findings in the investigation.
Students will be able to evaluate the credibility of external sources and discuss the risks and benefits of acting on unverified information.
Students will be able to collaborate to develop a strategic plan for next steps in the investigation.
Gameplan: Debrief Assignment, Unexpected Allies Quiz
Students uncover clues pointing to an insider threat within the tournament’s organizing committee. They perform a simulated data extraction from compromised accounts, synthesizing clues to start piecing together how the breach was orchestrated. Students review
Students will be able to define insider threats and explain how they can compromise organizational security.
Students will be able to understand and apply the principles of "least privilege" and "role-based access" to manage permissions effectively.
Students will be able to analyze an Access Control Matrix to identify unnecessary permissions and potential vulnerabilities.
Students will be able to evaluate the role of access controls in preventing insider threats and propose strategies for improvement.
Students will be able to collaborate with peers to create a breach timeline and discuss the impact of insider threats on organizational security.
Students will be able to reflect on how access control policies and periodic reviews can mitigate risks in real-world scenarios.
Gameplan: Data Extraction Assignment, Access Control Matrix, Tracing the Intruder Quiz
Students follow leads that reveal a decoy operation created by the cybercriminals to mislead investigators. They analyze new data logs that indicate breaches in other parts of the network, reinforcing the need for coordinated team analysis.
Students will be able to define decoy operations (red herrings) and explain their purpose in cybersecurity attacks.
Students will be able to analyze network logs to identify patterns that indicate potential decoy activity.
Students will be able to distinguish between genuine threats and distractions in cybersecurity investigations.
Students will be able to collaborate effectively with team members to evaluate evidence and draw conclusions about attackers’ strategies.
Students will be able to develop strategies for maintaining focus on critical targets when faced with misleading or distracting activities.
Gameplan: New Data Log Assignment, Tracing the Intruder Quiz
Teams analyze the collected data to trace the source of the suspicious activity. Students practice identifying phishing attempts and analyzing malware, finding the first suspect as conflicting evidence surfaces, deepening the mystery.
Students will be able to identify common phishing techniques and red flags.
Students will analyze simulated malware activity to determine its purpose and target.
Students will connect multiple pieces of evidence to identify a suspect and deepen their understanding of cybercriminal collaboration.
Gameplan: Spot The Phish, Analyzing Malware, Quiz
In this lesson, students learn how to use digital forensics tools. They examine network logs showing unusual access patterns, discovering early signs of intrusion. A fictional tournament organizer provides subtle hints, adding realism through role-play or video.
Students will be able to explain the purpose of network logs and their role in cybersecurity investigations.
Students will be able to analyze network data to identify suspicious access patterns.
Students will enhance teamwork and communication skills by collaborating on a forensic investigation.
Gameplan: Analyzing Network Logs, New Evidence Drop, Quiz
Students receive a mysterious email briefing about a potential cyberattack on the tournament. They learn basic cybersecurity concepts and encryption techniques while studying the history of cybersecurity threats. They analyze a decoded intercepted message, gaining initial clues about a suspicious network breach.
Students will be able to explain the importance of cybersecurity in protecting digital systems, particularly in the context of esports tournaments.
Students will be able to define encryption and describe how it is used to secure sensitive information from unauthorized access.
Students will be able to decode an encrypted message using a Caesar cipher and identify the significance of the decoded clue in the investigation.
Students will be able to analyze the potential impact of cyberattacks on esports events and propose initial strategies to address such threats.
Students will be able to collaborate effectively within teams to solve problems and interpret digital clues as part of a larger investigation.
Gameplan: Decrypting the Intercepted Message, The History of Cybersecreuity, Quiz